Description
EspoCRM 6.1.6 and prior suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in processing user-supplied avatar images. This issue was fixed in version 6.1.7 of the product.
Remediation
References
Related Vulnerabilities
WordPress Plugin Slideshow Multiple Cross-Site Scripting Vulnerabilities (2.1.14)
WordPress Plugin Advanced Woo Search Cross-Site Scripting (2.77)
OpenSSL Cryptographic Issues Vulnerability (CVE-2014-3566)
Oracle Database Server CVE-2009-0972 Vulnerability (CVE-2009-0972)
WordPress Plugin JW Player for Flash & HTML5 Video Cross-Site Request Forgery (2.1.11)